Legal
Privacy Policy
Last updated: July 31, 2026
Who this policy applies to
Apela One ("Apela One," "we," "us," or "our") is a B2B automation company based in Oklahoma City, Oklahoma. This policy explains how we collect, use, disclose, retain, and protect information when you visit our websites, use an Apela CRM workspace, connect a third-party account, contact us, or receive communications from us.
When we process information for a business customer inside that customer's workspace, the customer may be the data controller and Apela One may act as its service provider or processor. The customer's own privacy notice and instructions may also apply.
Information we collect
- Account and contact information, including name, business name, email address, phone number, login details, and support messages.
- CRM information that a customer or authorized user enters or imports, such as contacts, companies, opportunities, tasks, notes, forms, appointments, workflow data, and communication history.
- Integration information and tokens needed to provide an authorized connection to services such as Meta/Facebook and Instagram, Google Workspace and Business Profile, email, SMS, calendar, payments, or other services selected by the customer. We request only the scopes needed for the enabled feature.
- Message and marketing data, including message content, delivery events, opt-out requests, consent records, and phone-number information where required for A2P messaging.
- Technical information such as IP address, browser, device, pages viewed, approximate location, logs, cookies, and security events.
- AI and automation inputs and outputs submitted to a workspace, which are used to perform the requested workflow or assistant task.
How we use information
We use information to provide, secure, troubleshoot, and improve our website and services; authenticate users; operate CRM records, workflows, agents, email, SMS, calendar, forms, reporting, and SOP delivery; connect and synchronize authorized third-party accounts; communicate about accounts, support, billing, and service changes; prevent abuse and fraud; comply with law and platform requirements; and maintain business records.
We do not sell personal information. We do not use customer-connected data to build a public directory, expose customer records, or train a general-purpose model without the customer's written authorization.
Integrations and permissions
When you connect Meta, Google, email, calendar, messaging, or another service, you choose the permissions granted through that provider's authorization screen. We use the resulting access only to deliver the connected feature, such as syncing authorized leads, messages, comments, posts, business-profile data, calendar events, or email. Provider terms and privacy policies also apply.
Access tokens and credentials are stored with access controls and are not intentionally disclosed to other customers. You can disconnect an integration from the CRM or revoke authorization with the provider. Some provider permissions require separate approval and may not be available until the provider approves the application.
Email, SMS, and A2P messaging
We send transactional and marketing email or SMS only through configured business workspaces and according to the customer's instructions and applicable law. Customers are responsible for obtaining and documenting the required consent, identifying the sender, using approved templates and campaigns, and honoring opt-out requests. Recipients may opt out of marketing messages using the unsubscribe or STOP instructions provided in the message. We may retain consent, delivery, and opt-out records to demonstrate compliance and prevent further unwanted messages.
Service providers and disclosures
We use vetted providers for hosting, authentication, databases, email, SMS, analytics, payments, customer support, AI infrastructure, and third-party integrations. They process information only as needed to provide services to us and under contractual or technical safeguards. We may disclose information when required by law, to protect rights and safety, to investigate abuse, or as part of a merger, financing, or sale of business assets. We do not provide customer data to public authorities unless legally required.
Data minimization, retention, and security
We follow a data-minimization approach: we collect and request the least information and integration scope reasonably necessary for the feature, limit access by workspace and role, and avoid retaining information that is no longer needed. We retain data for the customer's account and legitimate business, security, legal, and compliance needs, then delete or de-identify it according to our retention procedures and the customer's instructions.
We use reasonable administrative, organizational, and technical safeguards, including authentication, role-based access, encrypted connections, logging, and protected credentials. No service can guarantee absolute security. We do not intentionally leak, publish, or sell customer records, and we do not provide customer documents to unrelated parties.
Your rights and deletion requests
Depending on your location and our role, you may request access to, correction of, export of, or deletion of personal information, or object to or restrict certain processing. A business customer may also request deletion of its workspace data, subject to backup, fraud-prevention, dispute, and legal-retention requirements. To disconnect Meta or another provider, use the CRM connector controls or revoke the authorization in the provider account.
Submit a request through our data-deletion instructions. We may verify identity and authority before acting. We do not discriminate against people for making a privacy request.
Cookies and analytics
We may use necessary cookies for security, authentication, and site operation, plus optional analytics or preference technologies. You can control cookies through your browser. Blocking necessary cookies may prevent parts of the site or CRM from working.
Children and international use
Our services are for businesses and are not directed to children under 13. We do not knowingly collect personal information from children. Information may be processed in the United States and other locations where our providers operate, subject to applicable safeguards.
Changes and contact
We may update this policy as our services, integrations, or legal obligations change. We will update the date above and, when appropriate, provide additional notice. For privacy questions or requests, use the contact options on our website and identify the account or workspace involved. We will route the request to the appropriate Apela One or customer contact.
Ready to put your growth on autopilot?
Book a free call and we'll map out the exact system to bring your business more leads, more bookings, and more reviews.